A method, device and system for distributed primality testing

By introducing two or more cooperative quality testing methods in the distributed system, using encryption keys and homomorphic operations, the problem of frequent quality testing in the distributed system is solved, efficient quality testing is achieved, and data security is ensured.

CN114697034BActive Publication Date: 2025-05-13AISINO CORPORATION +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202011618939.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-12-31
Publication Date
2025-05-13
Estimated Expiration
2040-12-31

AI Technical Summary

Technical Problem

In distributed systems, existing primary testing methods require multiple protocol communications, resulting in performance problems, especially when multiple users cooperate to conduct primary testing.

Method used

By introducing two or more professional test methods in the distributed system, using encryption keys and homomorphic operations, the test domain is extended from the target integer to the test domain plaintext, and it takes only one test to determine whether the integer is a prime number.

Benefits of technology

The number of prime tests is reduced, the performance of the distributed system is improved, and since the other party's prime data and parameters to be tested cannot be obtained between nodes, the data security is ensured.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114697034B_ABST
    Figure CN114697034B_ABST
Patent Text Reader

Abstract

The embodiment of the present invention provides a method, device and system for distributed primality testing. The method includes: a second participating node receives an encryption key and a test domain ciphertext parameter sent by a first participating node; the second participating node uses the encryption key to perform homomorphic operations on the test domain ciphertext parameter, the second prime number data and the second parameter to be tested to obtain the test domain ciphertext; the sum of the first parameter to be tested and the second parameter to be tested is a target integer; the second participating node sends the test domain ciphertext to the first participating node, so that the first participating node uses the decryption key corresponding to the encryption key to decrypt the test domain ciphertext to obtain the test domain plaintext; the second participating node receives the test parameter and the test domain plaintext sent by the first participating node, the test parameter is determined according to the random integer, the first prime number data, the first parameter to be tested and the test domain plaintext; the second participating node determines whether the random integer is a generator of the test domain plaintext.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data security technology, and in particular to a distributed primality testing method, device and system. Background Art

[0002] Prime numbers are the foundation of modern public key cryptography. How to determine whether a random integer is prime has a wide range of applications in the industry. For example, the key parameters p and q in the RSA encryption process must be prime numbers. Primality testing is a method of determining whether an integer is prime. To determine whether an integer is prime with 100% certainty is a computationally intensive task, and the number of tests required is super-polynomial. Especially when the integer being tested is relatively large, this completely accurate determination method becomes unavailable. Therefore, the commonly used primality testing methods are all probabilistic methods, that is, to determine whether an integer is prime with a very high probability of success.

[0003] In the prior art, multiple tests are required to determine whether an integer is prime with a very high probability. For example, the Rabin-Miller algorithm requires hundreds of tests. If a single user performs primality tests, hundreds of tests are tolerable; however, when multiple users cooperate to perform primality tests in a distributed system, hundreds of protocol communications are required, which becomes a serious performance problem. Therefore, how to reduce the number of primality tests is the primary problem that distributed cryptography technology must solve. Summary of the invention

[0004] The embodiments of the present invention provide a distributed primality test method, device and system for reducing the number of primality tests in a distributed system.

[0005] An embodiment of the present invention provides a distributed primality testing method, which is applied to a participating node in a distributed primality testing system, wherein the distributed primality testing system includes at least two participating nodes, wherein the second participating node is any participating node in the distributed primality testing system, and the first participating node is a node in the distributed primality testing system other than the second participating node. The distributed primality testing method includes:

[0006] The second participating node receives the encryption key and the test domain ciphertext parameter sent by the first participating node, where the test domain ciphertext parameter is determined by the first participating node using the encryption key, the first prime number data, and the first parameter to be tested;

[0007] The second participating node uses the encryption key to perform a homomorphic operation on the test domain ciphertext parameter, the second prime number data, and the second parameter to be tested to obtain a test domain ciphertext; the sum of the first parameter to be tested and the second parameter to be tested is a target integer;

[0008] The second participating node sends the test domain ciphertext to the first participating node, so that the first participating node decrypts the test domain ciphertext using the decryption key corresponding to the encryption key to obtain a test domain plaintext, where the test domain plaintext is equal to the product of the first prime number data, the second prime number data and the target integer;

[0009] The second participating node receives the test parameter and the test domain plaintext sent by the first participating node, where the test parameter is determined by the first participating node according to a random integer, the first prime number data, the first parameter to be tested, and the test domain plaintext;

[0010] The second participating node determines whether the random integer is a generator of the test domain plaintext according to the second prime number data, the second parameter to be tested, the test parameter, and the test domain plaintext;

[0011] If so, it is determined that the target integer is a prime number; if not, it is determined that the target integer is not a prime number.

[0012] In an optional embodiment, the test domain ciphertext parameters include a first prime number ciphertext obtained by encrypting first prime number data using the encryption key, and a first calculation result ciphertext obtained by obtaining a first calculation result based on the first prime number data and a first parameter to be tested and encrypting the first calculation result using the encryption key.

[0013] In an optional embodiment, the second participating node uses the encryption key to perform a homomorphic operation on the test domain ciphertext parameter, the second prime number data, and the second parameter to be tested to obtain the test domain ciphertext, including:

[0014] The second participating node calculates the second calculation result according to the first prime number ciphertext, the second prime number data and the second parameter to be measured, and encrypts the second calculation result by using the encryption key to obtain the second calculation result ciphertext;

[0015] The second participating node calculates a third calculation result according to the first calculation result ciphertext and the second prime number data, and encrypts the third calculation result using the encryption key to obtain a third calculation result ciphertext;

[0016] The second participating node performs a homomorphic operation using the second calculation result ciphertext and the third calculation result ciphertext to obtain the test domain ciphertext.

[0017] In an optional embodiment, the second participating node determines whether the random integer is a generator of the test domain plaintext according to the second prime number data, the second parameter to be tested, the test parameter, and the test domain plaintext, including:

[0018] The second participating node uses Fermat's theorem to determine whether the random integer is a generator of the test domain plaintext according to the second prime number data, the second parameter to be tested, the test parameter and the test domain plaintext.

[0019] In an optional embodiment, the first prime number data and the second prime number data are both strong prime numbers.

[0020] An embodiment of the present invention further provides a distributed primality testing device, the device comprising:

[0021] A receiving unit, configured to receive an encryption key and a test domain ciphertext parameter sent by a first participating node, wherein the test domain ciphertext parameter is determined by the first participating node using the encryption key, the first prime number data, and the first parameter to be tested;

[0022] a computing unit, configured to use the encryption key to perform homomorphic operation on the test domain ciphertext parameter, the second prime number data, and the second parameter to be tested to obtain the test domain ciphertext; the sum of the first parameter to be tested and the second parameter to be tested is a target integer;

[0023] a sending unit, configured to send the test domain ciphertext to the first participating node, so that the first participating node decrypts the test domain ciphertext using a decryption key corresponding to the encryption key to obtain a test domain plaintext, wherein the test domain plaintext is equal to the product of the first prime number data, the second prime number data and the target integer;

[0024] The receiving unit is further configured to receive a test parameter and the test domain plaintext sent by the first participating node, wherein the test parameter is determined by the first participating node according to a random integer, the first prime number data, the first parameter to be tested, and the test domain plaintext;

[0025] The calculation unit is further used to determine whether the random integer is a generator of the test domain plaintext based on the second prime number data, the second parameter to be tested, the test parameter and the test domain plaintext; if so, determine that the target integer is a prime number; if not, determine that the target integer is not a prime number.

[0026] In an optional embodiment, the test domain ciphertext parameters include a first prime number ciphertext obtained by encrypting first prime number data using the encryption key, and a first calculation result ciphertext obtained by obtaining a first calculation result based on the first prime number data and a first parameter to be tested and encrypting the first calculation result using the encryption key.

[0027] In an optional embodiment, the computing unit is specifically configured to:

[0028] Calculating according to the first prime number ciphertext, the second prime number data and the second parameter to be measured to obtain a second calculation result, and encrypting the second calculation result with the encryption key to obtain a second calculation result ciphertext;

[0029] Calculating a third calculation result according to the first calculation result ciphertext and the second prime number data, and encrypting the third calculation result using the encryption key to obtain a third calculation result ciphertext;

[0030] The second calculation result ciphertext and the third calculation result ciphertext are used to perform a homomorphic operation to obtain the test domain ciphertext.

[0031] In an optional embodiment, the computing unit is specifically configured to:

[0032] By using Fermat's theorem, it is determined whether the random integer is a generator of the test domain plaintext according to the second prime number data, the second parameter to be tested, the test parameter and the test domain plaintext.

[0033] In an optional embodiment, the first prime number data and the second prime number data are both strong prime numbers.

[0034] An embodiment of the present invention further provides a distributed primality testing system, the distributed primality testing system comprising at least two participating nodes, wherein the second participating node is any participating node in the distributed primality testing system, and the first participating node is a node in the distributed primality testing system other than the second participating node, and the distributed primality testing system comprises:

[0035] The first participating node is used to determine the test domain ciphertext parameter using the encryption key, the first prime number data, and the first parameter to be tested;

[0036] The second participating node is used to receive the encryption key and the test domain ciphertext parameter sent by the first participating node;

[0037] The second participating node is used to use the encryption key to perform a homomorphic operation on the test domain ciphertext parameter, the second prime number data, and the second parameter to be tested to obtain a test domain ciphertext, and send the test domain ciphertext to the first participating node; the sum of the first parameter to be tested and the second parameter to be tested is a target integer;

[0038] The first participating node is used to decrypt the test domain ciphertext using the decryption key corresponding to the encryption key to obtain a test domain plaintext, where the test domain plaintext is equal to the product of the first prime number data, the second prime number data and the target integer;

[0039] The first participating node is further used to determine a test parameter according to the random integer, the first prime number data, the first parameter to be tested and the test domain plain text;

[0040] The second participating node is used to receive the test parameter and the test domain plain text sent by the first participating node;

[0041] The second participating node is further used to determine whether the random integer is a generator of the test domain plaintext based on the second prime number data, the second parameter to be tested, the test parameter and the test domain plaintext; if so, determine that the target integer is a prime number; if not, determine that the target integer is not a prime number.

[0042] The distributed primality testing system in the embodiment of the present invention includes at least two participating nodes, wherein the second participating node is any participating node in the distributed primality testing system, and the first participating node is a node other than the second participating node in the distributed primality testing system. The first participating node holds first prime number data and a first parameter to be tested, and the second participating node holds second prime number data and a second parameter to be tested, wherein the sum of the first parameter to be tested and the second parameter to be tested is a target integer.

[0043] The first participating node determines an encryption key and a decryption key, and sends the encryption key to the second participating node. In the process of the first participating node and the second participating node jointly performing a primality test on the target integer, the first participating node calculates and encrypts the first prime number data and the first parameter to be tested to obtain a test domain ciphertext parameter and sends it to the second participating node, and the second participating node performs a homomorphic operation on the second prime number data, the second parameter to be tested, and the test domain ciphertext parameter to obtain the test domain ciphertext. In this process, since the second participating node does not have a decryption key, the second participating node cannot obtain the first prime number data and the first parameter to be tested.

[0044] The second participating node sends the test domain ciphertext to the first participating node, and the first participating node can use the decryption key to decrypt the test domain ciphertext to obtain the test domain plaintext. The test domain plaintext is equal to the product of the first prime number data, the second prime number data and the target integer. Because the target integer is the sum of the first parameter to be tested and the second parameter to be tested, the first participating node cannot use the test domain plaintext to infer the second prime number data and the second parameter to be tested. The first participating node randomly selects a random integer, determines the test parameter according to the random integer, the first prime number data, the first parameter to be tested and the test domain plaintext, and sends the test parameter and the test domain plaintext to the second participating node. The second participating node calculates according to the second prime number data, the second parameter to be tested, the test parameter and the test domain plaintext to determine whether the random integer is a generator of the test domain plaintext. If so, the target integer is determined to be a prime number; if not, the target integer is determined to be not a prime number.

[0045] In the above process, the test domain is extended from the target integer to the test domain plaintext, that is, the product of the first prime number data, the second prime number data and the target integer. Only one test is needed to determine whether the target integer is prime, and the probability of wrong judgment is less than 10. -16 At the same time, since the first participating node holds the first prime number data and the first parameter to be tested, and the second participating node holds the second prime number data and the second parameter to be tested, the first participating node and the second participating node cannot know each other's prime number data and the parameter to be tested during the test, thereby ensuring the security of data in the distributed system. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0047] Figure 1 A schematic diagram of the structure of a distributed primality testing system provided by an embodiment of the present invention;

[0048] Figure 2 A schematic diagram of a flow chart of a distributed primality testing method provided by an embodiment of the present invention;

[0049] Figure 3 A schematic flow chart of a distributed primality testing method provided for a specific embodiment of the present invention;

[0050] Figure 4 A schematic diagram of the structure of a distributed primality testing device provided by an embodiment of the present invention;

[0051] Figure 5A schematic diagram of the structure of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0052] The present invention will be further described in detail below in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0053] Existing methods and technologies mainly focus on optimizing the Rabin-Miller algorithm: the integer to be tested is divided by a small prime number, and only the integers that pass the small prime number test are subjected to the Rabin-Millier test. This method can reduce the number of Rabin-Miller tests by an order of magnitude, but it still requires dozens of tests. For distributed network applications, dozens of protocol communications are still an obvious performance bottleneck. Secondly, the small prime number trial division also requires the collaborative computing of all participants to be realized. Therefore, in a distributed application environment, this optimization method does not fundamentally solve the communication complexity problem of distributed primality testing.

[0054] In view of this, the embodiment of the present invention proposes a method and system for two parties to cooperate in primality testing. In the embodiment of the present invention, the primality test domain of the target integer p is replaced by Expand to Where n1 and n2 are two strong prime numbers, n1 is held by one of the participants, and n2 is held by the other participant. Then, in the domain In the primality test, Fermat's theorem is used to determine whether an integer is prime with only one test, and the probability of error is less than 10. -16 At the same time, the target integer p is not leaked to any participant during the test.

[0055] Furthermore, the primality test of the embodiment of the present invention can also be applied to three-party cooperation or even multi-party cooperation. For example, in a three-party cooperation, the primality test domain of the target integer p is Expand to Among them, n1, n2, and n3 are three strong prime numbers, and n1, n2, and n3 are held by one participant respectively. Then, in the domain Fermat's theorem is used for primality testing. Multi-party collaboration and so on.

[0056] refer to Figure 1 , which is a schematic diagram of the distributed primality test system architecture provided by the embodiment of the present application. The application scenario has at least two participating nodes 101, each participating node 101 stores its own prime number data and parameters to be tested, and different participating nodes 101 need to protect their own data privacy.

[0057] The participating nodes 101 may be connected directly or indirectly via wired or wireless communication, which is not limited in the present application.

[0058] Participating node 101 can be a terminal device or a server. It can be an independent physical server or a server cluster or distributed system composed of multiple physical servers. It can also be a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, as well as big data and artificial intelligence platforms. It is used in cloud electronic map products to meet the processing needs of large amounts of electronic map data.

[0059] When implemented based on cloud technology, participating node 101 can process data through cloud computing and cloud storage.

[0060] Cloud computing is a computing model that distributes computing tasks across a large number of resource pools, enabling various application systems to obtain computing power, storage space, and information services as needed. The network that provides resources is called a "cloud". From the user's perspective, the resources in the "cloud" are infinitely scalable and can be accessed at any time, used on demand, expanded at any time, and paid for by use. The cloud computing resource pool mainly includes: computing devices (virtualized machines, including operating systems), storage devices, and network devices.

[0061] Cloud storage is a new concept that extends and develops from the concept of cloud computing. A distributed cloud storage system (hereinafter referred to as storage system) refers to a storage system that uses cluster applications, grid technology, and distributed storage file systems to bring together a large number of different types of storage devices (storage devices are also called storage nodes) in the network through application software or application interfaces to work together and provide external data storage and business access functions.

[0062] Combine the following Figure 1 The application scenario shown illustrates the distributed primality testing method provided in the embodiment of the present application. The distributed primality testing method in the embodiment of the present application is applied to participating nodes in a distributed primality testing system, and the distributed primality testing system includes at least two participating nodes, wherein the second participating node is any participating node in the distributed primality testing system, and the first participating node is a node in the distributed primality testing system other than the second participating node. It should be noted that the number of first participating nodes can be one or more, and the embodiment of the present invention takes the number of first participating nodes as one as an example, and the execution process of multiple first participating nodes can be deduced in the same way as the method introduced in the embodiment of the present invention.

[0063] Please refer to Figure 2 , the present application embodiment provides a distributed primality testing method, such as Figure 2 As shown, the method includes:

[0064] Step S301: The first participating node determines the test domain ciphertext parameter using the encryption key, the first prime number data, and the first parameter to be tested;

[0065] Step S302: the second participating node receives the encryption key and the test domain ciphertext parameter sent by the first participating node;

[0066] Step S303: the second participating node uses the encryption key to perform a homomorphic operation on the test domain ciphertext parameter, the second prime number data and the second parameter to be tested to obtain a test domain ciphertext, and sends the test domain ciphertext to the first participating node; the sum of the first parameter to be tested and the second parameter to be tested is a target integer;

[0067] Step S304: the first participating node decrypts the test domain ciphertext using the decryption key corresponding to the encryption key to obtain a test domain plaintext, where the test domain plaintext is equal to the product of the first prime number data, the second prime number data and the target integer;

[0068] Step S305: the first participating node further determines a test parameter according to the random integer, the first prime number data, the first parameter to be tested and the test domain plain text;

[0069] Step S306: the second participating node receives the test parameter and the test domain plain text sent by the first participating node;

[0070] Step S307: the second participating node further determines whether the random integer is a generator of the test domain plaintext according to the second prime number data, the second parameter to be tested, the test parameter and the test domain plaintext;

[0071] If so, it is determined that the target integer is a prime number; if not, it is determined that the target integer is not a prime number.

[0072] In an embodiment of the present invention, the first participating node determines an encryption key and a decryption key, and sends the encryption key to the second participating node. In the process of the first participating node and the second participating node jointly performing a primality test on the target integer, the first participating node calculates and encrypts the first prime number data and the first parameter to be tested to obtain a test domain ciphertext parameter and sends it to the second participating node, and the second participating node performs a homomorphic operation on the second prime number data, the second parameter to be tested, and the test domain ciphertext parameter to obtain the test domain ciphertext. In this process, since the second participating node does not have a decryption key, the second participating node cannot obtain the first prime number data and the first parameter to be tested.

[0073] The second participating node sends the test domain ciphertext to the first participating node, and the first participating node can use the decryption key to decrypt the test domain ciphertext to obtain the test domain plaintext. The test domain plaintext is equal to the product of the first prime number data, the second prime number data and the target integer. Because the target integer is the sum of the first parameter to be tested and the second parameter to be tested, the first participating node cannot use the test domain plaintext to infer the second prime number data and the second parameter to be tested. The first participating node randomly selects a random integer, determines the test parameter according to the random integer, the first prime number data, the first parameter to be tested and the test domain plaintext, and sends the test parameter and the test domain plaintext to the second participating node. The second participating node calculates according to the second prime number data, the second parameter to be tested, the test parameter and the test domain plaintext to determine whether the random integer is a generator of the test domain plaintext. If so, the target integer is determined to be a prime number; if not, the target integer is determined to be not a prime number.

[0074] In the above process, the test domain is extended from the target integer to the test domain plaintext, that is, the product of the first prime number data, the second prime number data and the target integer. Only one test is needed to determine whether the target integer is prime, and the probability of wrong judgment is less than 10. -16 At the same time, since the first participating node holds the first prime number data and the first parameter to be tested, and the second participating node holds the second prime number data and the second parameter to be tested, the first participating node and the second participating node cannot know each other's prime number data and the parameter to be tested during the test, thereby ensuring the security of data in the distributed system.

[0075] Preferably, in the above process, both the first prime number data and the second prime number data are strong prime numbers. In cryptography, a prime number p is called a strong prime number when it meets the following conditions: p is a large number, and p-1 has a large prime factor. Since the product of strong prime numbers is difficult to decompose, the embodiment of the present invention uses strong prime numbers as prime number data to improve the security of data in the calculation process.

[0076] Furthermore, the above-mentioned test domain ciphertext parameters include a first prime number ciphertext obtained by encrypting the first prime number data using an encryption key, and a first calculation result ciphertext obtained by obtaining a first calculation result based on the first prime number data and the first parameter to be tested and encrypting the first calculation result using the encryption key.

[0077] Then, the second participating node uses the encryption key to perform homomorphic operation on the test domain ciphertext parameter, the second prime number data and the second parameter to be tested to obtain the test domain ciphertext, including:

[0078] The second participating node calculates the second calculation result according to the first prime number ciphertext, the second prime number data and the second parameter to be measured, and encrypts the second calculation result with the encryption key to obtain the second calculation result ciphertext;

[0079] The second participating node calculates a third calculation result according to the first calculation result ciphertext and the second prime number data, and encrypts the third calculation result using the encryption key to obtain a third calculation result ciphertext;

[0080] The second participating node performs homomorphic operation using the second calculation result ciphertext and the third calculation result ciphertext to obtain the test domain ciphertext.

[0081] During the specific implementation process, the first participating node and the second participating node use the principle of homomorphic encryption to determine the test domain ciphertext according to the first prime number data, the first parameter to be tested, the second prime number data and the second parameter to be tested, and then decrypt the test domain ciphertext to obtain the test domain plaintext.

[0082] Homomorphic encryption is a cryptographic technique based on the computational complexity theory of mathematical problems. The output obtained by processing the homomorphically encrypted data is decrypted, and the result is the same as the output obtained by processing the unencrypted original data in the same way. In other words, others can process the encrypted data, but the processing process will not reveal any original content. At the same time, after the user with the key decrypts the processed data, he will get the processed result.

[0083] In the above process, since the first participating node cannot know the second prime number data and the second parameter to be tested held by the second participating node, and the second participating node cannot know the first prime number data and the first parameter to be tested held by the first participating node, data security in the distributed system is guaranteed.

[0084] Further, the second participating node determines whether the random integer is a generator of the test domain plaintext according to the second prime number data, the second parameter to be tested, the test parameter, and the test domain plaintext, including:

[0085] The second participating node uses Fermat's theorem to determine whether the random integer is a generator of the test domain plaintext according to the second prime number data, the second parameter to be tested, the test parameter and the test domain plaintext.

[0086] It should be noted that the Fermat's theorem in the embodiment of the present invention is Fermat's little theorem. The content of the theorem is that if p is a prime number, and the integer a is not a multiple of p (i.e., a is ) then we have a p-1 ≡1(mod p). Therefore, in the embodiment of the present invention, an integer r is randomly determined by a random number generator, and whether the target integer in the test domain plaintext is a prime number is determined by testing whether r is a generator of the test domain plaintext.

[0087] The following is a specific example to introduce the above distributed primality test method. Assume that the integer n is an upper bound, and all integers tested will not exceed n. In the specific example of the present invention, there are two participants, denoted as A and S, each holding a parameter p to be tested of the target integer p. A and p S , that is, p = p A +p S . Let HE = (HKG, HE, HD) be an additive homomorphic encryption scheme, where HKG is the key generation algorithm, HE and HD are encryption and decryption algorithms respectively. If the ciphertexts corresponding to m1 and m2 are c1 and c2 respectively, then is the ciphertext of m1+m2, is the ciphertext of a×m1. (a,b) represents all natural numbers between a and b, excluding a and b. In the embodiment of the present invention, A and S cooperate to perform primality test on the target integer p and ensure the security of the target integer p. Figure 3 A flow chart of a distributed primality testing method in a specific embodiment is shown.

[0088] In the specific embodiment of the present invention, two participants are represented by A and S, and they each hold a parameter p to be measured of the target integer p. A and p S , that is, p = p A +p S .

[0089] Participant S executes the HKG algorithm to obtain the encryption key pkHE and the decryption key skHE.

[0090] Participant S uses a random number generator to select a strong prime number t S =(2φ S +1)∈(1,n), and calculate:

[0091] ct S=HE(pkHE,t S )...Formula 1

[0092] ctp S =HE(pkHE,p S ×t S )...Formula 2

[0093] Participant S sends pkHE, ct S and ctp S To Party A.

[0094] Party A uses a random number generator to select a strong prime number t A =(2φ A +1)∈(1,n), and calculate the test domain ciphertext ctp:

[0095]

[0096] Participant A sends ctp to participant S.

[0097] Participant S performs decryption calculation and obtains the test domain plaintext tp:

[0098] tp=HD(skHE,ctp)...Formula 4

[0099] Participant S uses a random number generator to select r∈(1,n) and calculates:

[0100]

[0101] Participant S sends tp, eφ S and eφp S To Party A.

[0102] Party A calculates:

[0103]

[0104] If v = 1, then the output is 1, indicating that p = p A +p S is a prime number; otherwise, that is, v≠1, the output is 0, indicating that p=p A +p S Not a prime number.

[0105] The embodiment of the present invention also provides a distributed primality testing device. Figure 4 A schematic diagram of the structure of a distributed primality test device provided by an embodiment of the present invention, the device comprising:

[0106] The receiving unit 401 is used to receive the encryption key and the test domain ciphertext parameter sent by the first participating node, where the test domain ciphertext parameter is determined by the first participating node using the encryption key, the first prime number data, and the first parameter to be tested;

[0107] A calculation unit 402 is used to use the encryption key to perform a homomorphic operation on the test domain ciphertext parameter, the second prime number data and the second parameter to be tested to obtain a test domain ciphertext; the sum of the first parameter to be tested and the second parameter to be tested is a target integer;

[0108] A sending unit 403 is configured to send the test domain ciphertext to the first participating node, so that the first participating node decrypts the test domain ciphertext using a decryption key corresponding to the encryption key to obtain a test domain plaintext, where the test domain plaintext is equal to the product of the first prime number data, the second prime number data and the target integer;

[0109] The receiving unit 401 is further configured to receive a test parameter and the test domain plaintext sent by the first participating node, wherein the test parameter is determined by the first participating node according to a random integer, the first prime number data, the first parameter to be tested, and the test domain plaintext;

[0110] The calculation unit 402 is further used to determine whether the random integer is a generator of the test domain plaintext based on the second prime number data, the second parameter to be tested, the test parameter and the test domain plaintext; if so, determine that the target integer is a prime number; if not, determine that the target integer is not a prime number.

[0111] Optionally, the test domain ciphertext parameters include a first prime number ciphertext obtained by encrypting first prime number data using the encryption key, and a first calculation result ciphertext obtained by obtaining a first calculation result based on the first prime number data and a first parameter to be tested and encrypting the first calculation result using the encryption key.

[0112] Optionally, the calculation unit 402 is specifically configured to:

[0113] Calculating according to the first prime number ciphertext, the second prime number data and the second parameter to be measured to obtain a second calculation result, and encrypting the second calculation result with the encryption key to obtain a second calculation result ciphertext;

[0114] Calculating a third calculation result according to the first calculation result ciphertext and the second prime number data, and encrypting the third calculation result using the encryption key to obtain a third calculation result ciphertext;

[0115] The second calculation result ciphertext and the third calculation result ciphertext are used to perform a homomorphic operation to obtain the test domain ciphertext.

[0116] Optionally, the calculation unit 402 is specifically configured to:

[0117] By using Fermat's theorem, it is determined whether the random integer is a generator of the test domain plaintext according to the second prime number data, the second parameter to be tested, the test parameter and the test domain plaintext.

[0118] Optionally, both the first prime number data and the second prime number data are strong prime numbers.

[0119] Figure 5 A schematic diagram of the structure of an electronic device provided in an embodiment of the present invention, the electronic device comprises: a processor 61, a communication interface 62, a memory 63 and a communication bus 64, wherein the processor 61, the communication interface 62, and the memory 63 communicate with each other through the communication bus 64;

[0120] The memory 63 stores a computer program. When the program is executed by the processor 61, the processor 61 performs the following steps:

[0121] Receiving an encryption key and a test domain ciphertext parameter sent by the first participating node, where the test domain ciphertext parameter is determined by the first participating node using the encryption key, the first prime number data, and the first parameter to be tested;

[0122] Using the encryption key, the test domain ciphertext parameter, the second prime number data, and the second parameter to be tested are homomorphically operated to obtain the test domain ciphertext; the sum of the first parameter to be tested and the second parameter to be tested is a target integer;

[0123] Sending the test domain ciphertext to the first participating node, so that the first participating node decrypts the test domain ciphertext using a decryption key corresponding to the encryption key to obtain a test domain plaintext, where the test domain plaintext is equal to the product of the first prime number data, the second prime number data and the target integer;

[0124] Receiving a test parameter and the test domain plaintext sent by the first participating node, where the test parameter is determined by the first participating node according to a random integer, the first prime number data, the first parameter to be tested, and the test domain plaintext;

[0125] Determining whether the random integer is a generator of the test domain plaintext according to the second prime number data, the second parameter to be tested, the test parameter, and the test domain plaintext;

[0126] If so, it is determined that the target integer is a prime number; if not, it is determined that the target integer is not a prime number.

[0127] Since the principle of solving the problem by the above electronic device is similar to that of the method based on distributed primality testing, the implementation of the above electronic device can refer to the implementation of the method, and the repeated parts will not be repeated.

[0128] The communication bus mentioned in the above electronic device can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. The communication bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, only one thick line is used in the figure, but it does not mean that there is only one bus or one type of bus.

[0129] The communication interface 62 is used for communication between the above electronic device and other devices.

[0130] The memory may include a random access memory (RAM) or a non-volatile memory (NVM), such as at least one disk memory. Optionally, the memory may also be at least one storage device located away from the aforementioned processor.

[0131] The above-mentioned processor can be a general-purpose processor, including a central processing unit, a network processor (Network Processor, NP), etc.; it can also be a digital signal processing processor (Digital Signal Processing, DSP), an application-specific integrated circuit, a field programmable gate array or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component, etc.

[0132] On the basis of the above embodiments, an embodiment of the present invention further provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program executable by a processor, and when the program runs on the processor, the processor implements the following steps when executing:

[0133] Receiving an encryption key and a test domain ciphertext parameter sent by the first participating node, where the test domain ciphertext parameter is determined by the first participating node using the encryption key, the first prime number data, and the first parameter to be tested;

[0134] Using the encryption key, the test domain ciphertext parameter, the second prime number data, and the second parameter to be tested are homomorphically operated to obtain the test domain ciphertext; the sum of the first parameter to be tested and the second parameter to be tested is a target integer;

[0135] Sending the test domain ciphertext to the first participating node, so that the first participating node decrypts the test domain ciphertext using a decryption key corresponding to the encryption key to obtain a test domain plaintext, where the test domain plaintext is equal to the product of the first prime number data, the second prime number data and the target integer;

[0136] Receiving a test parameter and the test domain plaintext sent by the first participating node, where the test parameter is determined by the first participating node according to a random integer, the first prime number data, the first parameter to be tested, and the test domain plaintext;

[0137] Determining whether the random integer is a generator of the test domain plaintext according to the second prime number data, the second parameter to be tested, the test parameter, and the test domain plaintext;

[0138] If so, it is determined that the target integer is a prime number; if not, it is determined that the target integer is not a prime number.

[0139] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented in one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that include computer-usable program code.

[0140] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0141] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0142] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0143] Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalents, the present application is also intended to include these modifications and variations.

Claims

1. A method for distributed primality testing, applied to participating nodes in a distributed primality testing system, wherein the distributed primality testing system includes at least two participating nodes, wherein the second participating node is any participating node in the distributed primality testing system, and the first participating node is a node in the distributed primality testing system other than the second participating node, characterized in that: The distributed primality testing method comprises: The second participating node receives the encryption key and the test domain ciphertext parameter sent by the first participating node, the test domain ciphertext parameter includes a first prime number ciphertext and a first calculation result ciphertext, the first prime number ciphertext is obtained by the first participating node encrypting the first prime number data by using the encryption key, and the first calculation result ciphertext is obtained by the first participating node obtaining a first calculation result according to the first prime number data and the first parameter to be tested and encrypting the first calculation result by using the encryption key; The second participating node calculates the second calculation result according to the first prime number ciphertext, the second prime number data and the second parameter to be measured, and encrypts the second calculation result by using the encryption key to obtain the second calculation result ciphertext; The second participating node calculates a third calculation result according to the first calculation result ciphertext and the second prime number data, and encrypts the third calculation result using the encryption key to obtain a third calculation result ciphertext; The second participating node performs homomorphic operation using the second calculation result ciphertext and the third calculation result ciphertext to obtain the test domain ciphertext; the sum of the first parameter to be tested and the second parameter to be tested is a target integer; The second participating node sends the test domain ciphertext to the first participating node, so that the first participating node decrypts the test domain ciphertext using the decryption key corresponding to the encryption key to obtain a test domain plaintext, where the test domain plaintext is equal to the product of the first prime number data, the second prime number data and the target integer; The second participating node receives the test parameter and the test domain plaintext sent by the first participating node, where the test parameter is determined by the first participating node according to a random integer, the first prime number data, the first parameter to be tested, and the test domain plaintext; The second participating node determines whether the random integer is a generator of the test domain plaintext according to the second prime number data, the second parameter to be tested, the test parameter, and the test domain plaintext; If so, it is determined that the target integer is a prime number; if not, it is determined that the target integer is not a prime number.

2. The method according to claim 1, characterized in that The second participating node determines whether the random integer is a generator of the test domain plaintext according to the second prime number data, the second parameter to be tested, the test parameter, and the test domain plaintext, including: The second participating node uses Fermat's theorem to determine whether the random integer is a generator of the test domain plaintext according to the second prime number data, the second parameter to be tested, the test parameter and the test domain plaintext.

3. The method according to claim 1 or 2, characterized in that: The first prime number data and the second prime number data are both strong prime numbers.

4. A distributed primality testing device, characterized in that: The device comprises: a receiving unit, configured to receive an encryption key and a test domain ciphertext parameter sent by a first participating node, wherein the test domain ciphertext parameter includes a first prime number ciphertext and a first calculation result ciphertext, wherein the first prime number ciphertext is obtained by the first participating node encrypting first prime number data using the encryption key, and the first calculation result ciphertext is obtained by the first participating node obtaining a first calculation result according to the first prime number data and a first parameter to be tested and encrypting the first calculation result using the encryption key; a calculation unit, configured to calculate a second calculation result according to the first prime number ciphertext, the second prime number data and the second parameter to be measured, and encrypt the second calculation result using the encryption key to obtain a second calculation result ciphertext; calculate a third calculation result according to the first calculation result ciphertext and the second prime number data, and encrypt the third calculation result using the encryption key to obtain a third calculation result ciphertext; perform homomorphic operation on the second calculation result ciphertext and the third calculation result ciphertext to obtain the test domain ciphertext; the sum of the first parameter to be measured and the second parameter to be measured is a target integer; a sending unit, configured to send the test domain ciphertext to the first participating node, so that the first participating node decrypts the test domain ciphertext using a decryption key corresponding to the encryption key to obtain a test domain plaintext, wherein the test domain plaintext is equal to the product of the first prime number data, the second prime number data and the target integer; The receiving unit is further configured to receive a test parameter and the test domain plaintext sent by the first participating node, wherein the test parameter is determined by the first participating node according to a random integer, the first prime number data, the first parameter to be tested, and the test domain plaintext; The calculation unit is further used to determine whether the random integer is a generator of the test domain plaintext based on the second prime number data, the second parameter to be tested, the test parameter and the test domain plaintext; if so, determine that the target integer is a prime number; if not, determine that the target integer is not a prime number.

5. The device according to claim 4, characterized in that The computing unit is specifically used for: By using Fermat's theorem, it is determined whether the random integer is a generator of the test domain plaintext according to the second prime number data, the second parameter to be tested, the test parameter and the test domain plaintext.

6. The device according to claim 4 or 5, characterized in that The first prime number data and the second prime number data are both strong prime numbers.

7. A distributed primality testing system, comprising at least two participating nodes, wherein: The second participating node is any participating node in the system of the distributed primality test, and the first participating node is a node in the system of the distributed primality test other than the second participating node, characterized in that the first participating node is used to determine the test domain ciphertext parameters by using an encryption key, a first prime number data, and a first parameter to be tested, the test domain ciphertext parameters include a first prime number ciphertext and a first calculation result ciphertext, the first prime number ciphertext is obtained by the first participating node encrypting the first prime number data by using the encryption key, and the first calculation result ciphertext is obtained by the first participating node obtaining a first calculation result according to the first prime number data and the first parameter to be tested and encrypting the first calculation result by using the encryption key; The second participating node is used to receive the encryption key and the test domain ciphertext parameter sent by the first participating node; The second participating node is used to calculate according to the first prime number ciphertext, the second prime number data and the second parameter to be measured to obtain a second calculation result, and encrypt the second calculation result with the encryption key to obtain a second calculation result ciphertext; The second participating node is used to calculate a third calculation result according to the first calculation result ciphertext and the second prime number data, and encrypt the third calculation result using the encryption key to obtain a third calculation result ciphertext; The second participating node is used to perform homomorphic operation using the second calculation result ciphertext and the third calculation result ciphertext to obtain the test domain ciphertext, and send the test domain ciphertext to the first participating node; the sum of the first parameter to be tested and the second parameter to be tested is a target integer; The first participating node is used to decrypt the test domain ciphertext using the decryption key corresponding to the encryption key to obtain a test domain plaintext, where the test domain plaintext is equal to the product of the first prime number data, the second prime number data and the target integer; The first participating node is further used to determine a test parameter according to the random integer, the first prime number data, the first parameter to be tested and the test domain plain text; The second participating node is used to receive the test parameter and the test domain plain text sent by the first participating node; The second participating node is further used to determine whether the random integer is a generator of the test domain plaintext based on the second prime number data, the second parameter to be tested, the test parameter and the test domain plaintext; if so, determine that the target integer is a prime number; if not, determine that the target integer is not a prime number.

Citation Information

Patent Citations

  • Primeness determining method through order trying division method

    CN103514141A

  • Method and device for testing large prime number

    CN106685660A